<?php require '../includes/security.php'; ?>
<?php require_once('../Connections/connection.php'); ?>
<?php

$id_stanza = $_GET['id_stanza'];


function GetSQLValueString($theValue, $theType, $theDefinedValue = "", $theNotDefinedValue = "") 
{
  $theValue = (!get_magic_quotes_gpc()) ? addslashes($theValue) : $theValue;

  switch ($theType) {
    case "text":
      $theValue = ($theValue != "") ? "'" . $theValue . "'" : "NULL";
      break;    
    case "long":
    case "int":
      $theValue = ($theValue != "") ? intval($theValue) : "NULL";
      break;
    case "double":
      $theValue = ($theValue != "") ? "'" . doubleval($theValue) . "'" : "NULL";
      break;
    case "date":
      $theValue = ($theValue != "") ? "'" . $theValue . "'" : "NULL";
      break;
    case "defined":
      $theValue = ($theValue != "") ? $theDefinedValue : $theNotDefinedValue;
      break;
  }
  return $theValue;
}

$editFormAction = $_SERVER['PHP_SELF'];
if (isset($_SERVER['QUERY_STRING'])) {
  $editFormAction .= "?" . htmlentities($_SERVER['QUERY_STRING']);
}

if ((isset($_POST["MM_update"])) && ($_POST["MM_update"] == "form1")) {
  $updateSQL = sprintf("UPDATE oggetto SET Nome=%s, Descrizione=%s WHERE id_oggetto=%s",
                       GetSQLValueString($_POST['Nome'], "text"),
                       GetSQLValueString($_POST['Descrizione'], "text"),
                       GetSQLValueString($_POST['id_oggetto'], "int"));

  mysql_select_db($database_setroma, $setroma);
  $Result1 = mysql_query($updateSQL, $setroma) or die(mysql_error());

  $updateGoTo = "index.php?id_stanza=".$_POST['id_stanza'];
  if (isset($_SERVER['QUERY_STRING'])) {
    $updateGoTo .= (strpos($updateGoTo, '?')) ? "&" : "?";
    $updateGoTo .= $_SERVER['QUERY_STRING'];
  }
  header(sprintf("Location: %s", $updateGoTo));
}

$colname_oggetto = "-1";
if (isset($_GET['id_oggetto'])) {
  $colname_oggetto = (get_magic_quotes_gpc()) ? $_GET['id_oggetto'] : addslashes($_GET['id_oggetto']);
}
mysql_select_db($database_setroma, $setroma);
$query_oggetto = sprintf("SELECT * FROM oggetto WHERE id_oggetto = %s", $colname_oggetto);
$oggetto = mysql_query($query_oggetto, $setroma) or die(mysql_error());
$row_oggetto = mysql_fetch_assoc($oggetto);
$totalRows_oggetto = mysql_num_rows($oggetto);
?><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1" />
<title>Untitled Document</title>
<script type="text/javascript" src="../fckeditor/fckeditor.js"></script>
<link rel='stylesheet' type='text/css' href='../styles/style.css' />
</head>

<body>
<h1>Modifica Oggetto</h1>
<form method="post" name="form1" action="<?php echo $editFormAction; ?>">
  <table>
    <tr valign="baseline">
      <td nowrap align="right">Nome:</td>
      <td><input type="text" name="Nome" value="<?php echo $row_oggetto['Nome']; ?>" size="32"></td>
    </tr>
    <tr valign="baseline">
      <td nowrap align="right" valign="top">Descrizione:</td>
      <td>
	  
	  <?php
	
if ($row_oggetto['tipologia']==1) {
	
	
include("../fckeditor/fckeditor.php") ;
$oFCKeditor = new FCKeditor('Descrizione') ;
$oFCKeditor->BasePath	= '../fckeditor/' ;
$oFCKeditor->Width = '640px';
$oFCKeditor->Height = '480px';
$oFCKeditor->Value		=  $row_oggetto['Descrizione'];
$oFCKeditor->Create() ;
} else {
?>
N.A.
<input type="hidden" name="Descrizione" value='<?php echo $row_oggetto['Descrizione']; ?>'>

<?php	
	
}
?>

<input type=hidden name="id_stanza" value="<?php echo $id_stanza; ?>">
	  
	  </td>
    </tr>
    <tr valign="baseline">
      <td nowrap align="right">&nbsp;</td>
      <td><input type="submit" value="Salva le modifiche"> &nbsp; <input type="button" value="Annulla" onclick="javascript:history.back()"></td>
    </tr>
  </table>
  <input type="hidden" name="MM_update" value="form1">
  <input type="hidden" name="id_oggetto" value="<?php echo $row_oggetto['id_oggetto']; ?>">
</form>
<p>&nbsp;</p>
</body>
</html>
<?php
mysql_free_result($oggetto);
?>
